FortiMail CVE-2026-104286 Is Exploited With No Fixed Release, and the Workaround Is Turning Off a Feature
Security / news
FortiMail CVE-2026-104286 Is Exploited With No Fixed Release, and the Workaround Is Turning Off a Feature
An unauthenticated path-traversal bug scoring 9.8 lets an attacker write files to FortiMail 7.2 through 8.0. CISA's deadline is October 4; Fortinet had no patch when the advisory went out.
An unauthenticated attacker who can send crafted HTTP or HTTPS requests to a FortiMail management interface can write files onto the appliance's operating system through CVE-2026-104286. The flaw is a path traversal combined with improper handling of NULL bytes, and it scores 9.8 under CVSS 3.1. The US Cybersecurity and Infrastructure Security Agency added it to its Known Exploited Vulnerabilities catalog on October 1, 2026, citing "evidence of active exploitation."
No fixed release was available when the advisory was published, according to watchTowr's FAQ. The only options are a feature switch and network restriction, described below.
Affected versions
Every supported branch is in range, per Truesec and watchTowr.
| Branch | Vulnerable versions | Fixed release |
|---|---|---|
| FortiMail 8.0 | 8.0.0 to 8.0.1 | None at publication |
| FortiMail 7.6 | 7.6.0 to 7.6.6 | None at publication |
| FortiMail 7.4 | 7.4.0 to 7.4.8 | None at publication |
| FortiMail 7.2 | 7.2.0 to 7.2.9 | None at publication |
The workaround and what it costs
Fortinet's two mitigations are to disable the Identity-Based Encryption (IBE) feature, or to limit the management interface to trusted private networks. Truesec gives the command as config system encryption ibe set status disable end. Disabling IBE stops the feature working, so any organisation that sends encrypted mail through it has to choose between the exposure and the function. Neither source says how many FortiMail customers use IBE.
Cutting internet access to the management interface needs no feature loss, and it is the cheaper of the two for most operators. It does not help an appliance that is already compromised.
What an attacker gets
A file write is not code execution by itself. Truesec says that placing a file on the system gives the attacker a route to run commands, which can lead to "full control of the mail gateway, exposing stored mail, credentials, and other systems it connects to." The step from file write to command execution is described in general terms and not demonstrated in either source.
The score is justified by the preconditions: no authentication, and a network path to the management interface. It would matter far less if that interface were never exposed, which is the point of the second mitigation.
Signs of compromise
Truesec lists suspicious log entries, file modifications including /bin/smit and /data/lib/liblog.so, and command-execution patterns tied to exploitation attempts. watchTowr's advice is to preserve forensic artefacts first, cross-check Fortinet's published indicators of compromise, apply a mitigation, and rotate administrative credentials afterwards.
watchTowr gives CISA's remediation deadline for federal civilian agencies as October 4, 2026, three days after the listing. With no fixed release, an agency can meet it only through the mitigations.
The exploitation claim rests on CISA's listing. Neither source retrieved names the attacker, the first observed attack date or the number of victims. The site's reporting on GPT-6.1 Sol's Critical cyber rating and on Gemini 4 Argon reaching defenders first concerns models that may shorten patch cycles. A patch for this bug has not appeared yet, so there is no cycle to shorten.
Operators should apply one mitigation today and watch for a fixed release on each of the four branches.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 03Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 04Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.